2026-06-05: Cisco discloses seventh SD-WAN zero-day this year, now actively exploited for root escalation with
SHOW NOTES - 2026-06-05
STORIES COVERED
* June 5, 2026
* Today:
* Cisco SD-WAN Zero-Day Actively Exploited (CVE-2026-20245) [https://www.bleepingcomputer.com/news/security/new-cisco-sd-wan-flaw-exploited-in-zero-day-attacks-to-gain-root/] [Critical Alerts]
* Cisco Unified CM Critical SSRF with Public PoC (CVE-2026-20230) [https://www.bleepingcomputer.com/news/security/cisco-warns-of-critical-unified-cm-flaw-with-poc-exploit-code/] [Critical Alerts]
* Windows 11 Zero-Day (CVE-2026-0257) [https://www.sentinelone.com/blog/the-good-the-bad-and-the-ugly-in-cybersecurity-week-23-7/] [Critical Alerts]
* AI Agents as Insider Threat [https://cyberscoop.com/ai-agent-insider-threat-cybersecurity-dtex/] [Business & Infrastructure Threats]
* Claude Code GitHub Action Repository Takeover [https://thehackernews.com/2026/06/claude-code-github-action-flaw-let-one.html] [Business & Infrastructure Threats]
* Microsoft Agentic AI Failure Modes v2.0 [https://www.microsoft.com/en-us/security/blog/2026/06/04/updating-taxonomy-failure-modes-agentic-ai-systems-year-red-teaming-taught-us/] [Business & Infrastructure Threats]
* UN World Food Programme Gaza Breach (600,000 Households) [https://www.bleepingcomputer.com/news/security/un-world-food-programme-breach-affects-600-000-gaza-households/] [Business & Infrastructure Threats]
* DentaQuest Breach (2.6 Million Accounts) [https://www.bleepingcomputer.com/news/security/dentaquest-data-breach-exposed-info-of-26-million-accounts/] [Business & Infrastructure Threats]
* China-Linked TA4922 Expands to Europe [https://www.sentinelone.com/blog/the-good-the-bad-and-the-ugly-in-cybersecurity-week-23-7/] [Ransomware & Extortion]
* IronWorm npm Supply Chain Attack (36 Packages) [https://www.bleepingcomputer.com/news/security/new-ironworm-malware-hits-36-packages-in-npm-supply-chain-attack/] [Ransomware & Extortion]
* Russian Mobile Spyware Operation [https://thehackernews.com/2026/06/threatsday-bulletin-ai-agents-gone.html] [Ransomware & Extortion]
* Microsoft M365 Copilot RCE (CVE-2026-45497) [https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45497] [Windows / AD Security]
* Windows Driver Update Issue [https://www.bleepingcomputer.com/news/microsoft/microsoft-blames-unexpected-windows-driver-updates-on-caching-issue/] [Windows / AD Security]
* Chrome 149 Patches Record 429 Vulnerabilities [https://www.securityweek.com/chrome-149-patches-429-vulnerabilities/] [General Security News]
* Hola Browser Supply Chain Compromise [https://www.bleepingcomputer.com/news/security/hola-browser-for-windows-compromised-to-deliver-cryptominer/] [General Security News]
* Everest Forms Pro WordPress RCE Actively Exploited (CVE-2026-3300) [https://thehackernews.com/2026/06/hackers-exploit-critical-everest-forms.html] [General Security News]
* Magecart Campaign Abuses Stripe API [https://www.bleepingcomputer.com/news/security/credit-card-theft-campaign-abuses-stripe-to-host-stolen-payment-info/] [General Security News]
* VIP Keylogger via JavaScript Loaders [https://isc.sans.edu/diary/rss/33054] [General Security News]
* FlutterShell macOS Malvertising [https://thehackernews.com/2026/06/fluttershell-backdoor-spreads-to-macos.html] [General Security News]
* FIFA World Cup 2026 Scams [https://thehackernews.com/2026/06/fifa-world-cup-2026-scams-are-already.html] [General Security News]
* Hitachi Energy ICS Vulnerabilities [https://www.cisa.gov/news-events/ics-advisories/icsa-26-155-04] [Vulnerability Disclosures]
* B&R PPT30 OPC-UA DoS (CVE-2025-11482) [https://www.cisa.gov/news-events/ics-advisories/icsa-26-155-03] [Vulnerability Disclosures]
CVES REFERENCED
CVE-2024-8176, CVE-2025-11482, CVE-2025-20309, CVE-2025-59375, CVE-2026-0257, CVE-2026-10881, CVE-2026-10882, CVE-2026-10883, CVE-2026-20045, CVE-2026-20127, CVE-2026-20182, CVE-2026-20230, CVE-2026-20245, CVE-2026-25253, CVE-2026-3300, CVE-2026-45497, CVE-2026-7310
INDICATORS OF COMPROMISE
IP Addresses:
202.56.2.126, 209.146.60.26, 15.235.166.18, 185.78.165.153
Read the full brief [https://carolinacleartech.com/brief/2026-06-05/]
Kommentit
0Ole ensimmäinen kommentoija
Rekisteröidy nyt ja liity Cyber Threat Brief-yhteisöön!